Skip to content

NuGet dependency vulnerabilities #146

@jmisharp

Description

@jmisharp

Current version 6.2.1 of the Respawn package has a security vulnerability because of an old dependency to Microsoft.Data.SqlClient, that has a dependency to System.Drawing.Common@5.0.0.

.NET Core Remote Code Execution Vulnerability (This package is used under: Respawn@6.2.1->Microsoft.Data.SqlClient@4.0.5->System.Configuration.ConfigurationManager@5.0.0->System.Security.Permissions@5.0.0->System.Windows.Extensions@5.0.0->System.Drawing.Common@5.0.0)

Please update to mitigate this vulnerability.

CVE description: https://nvd.nist.gov/vuln/detail/CVE-2021-24112

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions